Proofpoint researchers Michael Raggi and Dennis Schwarz reported on a group of hackers who attempted to infiltrate U.S. utilities in July. On Thursday, the researchers said that between July 19 and 25, phishing emails were sent to three utilities.

The phishing emails purported to come from an engineering licensing board, the US National Council of Examiners for Engineering and Surveying, informing victims that they had failed an exam. This is a common technique in phishing attacks and has been seen in fake student loan claims or tax claims, etc. The result? If the recipient trusts the email, they will follow the instructions and allow their system to be infected.
The phishing emails contained a Word document titled Result Notice.doc. This injected malicious code into the recipient’s system . If a victim opens the file and activates the VBA macros, three Privacy Enhanced Mail (PEM) files are injected. tempgup.txt, tempgup2.txt, and tempsodom.txt. These are decoded and converted into a notepad file in the form of GUP.exe, libcurl.dll – a malicious loader, and sodom.txt, a file containing command and control (C2) configuration parameters for the code. This is how the LookBack malware is injected .

LookBack is a Trojan, written in C++, which is able to view system data, execute code, hack, steal and delete files, take screenshots, move and click the mouse without the user, etc. LookBack is also able to create a C2 channel and a proxy serverinorder to extract and send system information to the server .
Proofpoint has linked these phishing attacks to APT campaigns in 2018 that were linked to Japanese companies. FireEye researchers said that the well-known APT10, or Menupass, which attacks media companies, appears to be Chinese and tends to follow the Japanese example. If it is the same hackers, this could mean that APT 10 is now targeting the United States.
